matrix-synapse is vulnerable to Improper Input Validation
5
Low Risk
On some endpoints, Synapse accepts extraneous trailing suffix data on the request path. When a reverse proxy normalises paths for routing (for example converting /a/../b to /b), the differing interpretation between the proxy and Synapse can bypass reverse-proxy routing rules and expose unintended endpoints. Because sensitive endpoints such as Admin APIs still require a valid access token, this is a loss of defence in depth rather than a directly exploitable flaw. The fix stops Synapse from accepting the extraneous suffix data.
You are affected if you are using a version that falls within the vulnerable range and you rely on a reverse proxy that normalises request paths to restrict access to endpoints.
matrix-synapse is vulnerable to Improper Input Validation in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant